What is the Machinery Regulation?
The Machinery Regulation, Regulation (EU) 2023/1230, is the European law that sets the safety requirements for machinery and replaces the Machinery Directive 2006/42/EC from 20 January 2027. Unlike a directive, a regulation applies directly in all member states without transposition into national law. Its main innovations concern digitalisation: cybersecurity becomes a safety requirement, there are rules for machines with self-learning AI, and instructions may be supplied digitally.
ποΈ When does the Machinery Regulation apply?
| Date | Milestone |
|---|---|
| 29 June 2023 | Published in the Official Journal of the EU |
| 19 July 2023 | Entry into force |
| 20 January 2027 | Applies; the Machinery Directive is repealed |
Machinery placed on the market before 20 January 2027 remains under the old Machinery Directive and does not need to be reassessed. Anything placed on the market on or after that date needs an EU declaration of conformity under 2023/1230 for CE marking.
π What cybersecurity requirements does the Machinery Regulation set?
For the first time, European machinery legislation treats digital attacks as a safety risk. Two essential requirements in Annex III are key:
- 1.1.9 Protection against corruption β hardware and software that affect safety must withstand accidental and intentional tampering. The machine must record evidence of legitimate and illegitimate interventions in safety-relevant software or settings.
- 1.2.1 Safety and reliability of control systems β control systems must withstand reasonably foreseeable malicious attempts by third parties that lead to a hazardous situation.
In practice this means, among other things: access control on the PLC and safety PLC, logging of changes, signed firmware and a risk assessment that also covers cyber threats. Standards from the IEC 62443 series help demonstrate compliance with these requirements.
π How does it differ from the Machinery Directive?
| Topic | Machinery Directive 2006/42/EC | Machinery Regulation 2023/1230 |
|---|---|---|
| Legal form | Directive, transposed nationally | Regulation, directly applicable |
| Cybersecurity | Not explicit | Essential requirements 1.1.9 and 1.2.1 |
| AI and self-evolving behaviour | Not covered | Risk assessment over the whole lifetime |
| Instructions | On paper | Digital allowed (paper on request) |
| Substantial modification | Not defined | Explicit: whoever substantially modifies a machine becomes the manufacturer |
| Third-party assessment | Annex IV machinery | Extended list in Annex I, part A mandatory third-party |
π§± Who does the Machinery Regulation apply to?
The regulation applies to manufacturers, importers and distributors of machinery, interchangeable equipment, safety components, chains, cables and partly completed machinery. End users are affected too: anyone who substantially modifies an existing machine, for example with new control software that changes the safety functions, must then meet the requirements as a manufacturer.
For machine builders and OT departments, this gives change management and configuration management of control systems a legal dimension as well.
π§ How does the Machinery Regulation relate to other legislation?
- Cyber Resilience Act β products with digital elements must comply with the CRA; CRA compliance gives a presumption of conformity with the cybersecurity requirements of the Machinery Regulation
- AI Act β AI systems acting as a safety component in a machine are high-risk AI
- NIS2 β targets the operator of an installation, not the product
- Harmonised standards β such as ISO 12100 (risk assessment) and ISO 13849 / IEC 62061 (functional safety)
π οΈ How do you prepare as a machine builder?
- Review your portfolio β which machines will you still place on the market after 20 January 2027, and do they fall under the list in Annex I (mandatory third-party assessment)?
- Extend the risk assessment β beyond mechanical and electrical hazards, include tampering and cyberattacks that could lead to unsafe situations
- Secure the control system β access control on the PLC and safety PLC, signed firmware, encrypted connections for remote maintenance
- Record interventions β the machine must keep evidence of changes to safety-relevant software and settings
- Update the documentation β declaration of conformity under 2023/1230, digital instructions, a software bill of materials (SBOM) for the control system
- Follow the standards β the harmonised standards are being revised; IEC 62443-4-2 and the Cyber Resilience Act already help substantiate compliance
β Frequently asked questions
When does the Machinery Regulation take effect?
The Machinery Regulation (EU) 2023/1230 entered into force on 19 July 2023 and applies from 20 January 2027. From that date every machine placed on the EU market must comply with the new regulation. The Machinery Directive 2006/42/EC is then repealed.
Does an existing machine need to be reassessed?
No, machines lawfully placed on the market before 20 January 2027 do not need to be reassessed. That changes if the machine is substantially modified afterwards. Whoever carries out a substantial modification becomes the manufacturer and must assess the modified machine under the Machinery Regulation.
What is a substantial modification under the Machinery Regulation?
A substantial modification is a physical or digital change after commissioning that was not foreseen by the manufacturer and that introduces a new hazard or increases an existing risk, requiring new protective measures. A software update to the control system that changes safety functions can also qualify.
What cybersecurity requirements does the Machinery Regulation set?
The Machinery Regulation requires in Annex III, point 1.1.9, that safety-relevant hardware and software are protected against accidental and intentional corruption, and that interventions are recorded. Requirement 1.2.1 demands that control systems withstand reasonably foreseeable malicious attempts by third parties that lead to hazardous situations.
May instructions be supplied digitally?
Yes, under the Machinery Regulation the instructions for use may be supplied digitally, for example via a website or QR code. At the buyerβs request, the manufacturer must provide a paper version free of charge. For machinery intended for non-professional users, paper safety information remains mandatory.
π In summary
The Machinery Regulation (EU) 2023/1230 replaces the Machinery Directive on 20 January 2027 and makes protection against tampering and cyberattacks a condition for CE marking. Machine builders need to build security into their designs now; users who substantially modify machines become manufacturers themselves.
